Default deny / secure by default
Why important?
Secure defaults reduce risk and audit effort (less "configuration debt").
How measured?
Scale 0–5 + N/A:
- 0 = Insecure defaults / default allow (high exposure)
- 1 = Some secure defaults, but inconsistent
- 2 = Secure defaults only in parts/optional, no consistent standard
- 3 = Secure by default for the core scope, clear baselines
- 4 = Secure by default broadly + standard blueprints/landing zones
- 5 = Secure by default + demonstrable baselines (audit/controls) + continuous assurance
- N/A = no reliable evidence
Validation questions (RFP)
- Which secure defaults apply (private by default, encryption by default, logging by default)? What has to be switched on actively? Is public exposure technically prevented?
Scores comparison
| Providers | Score | |
|---|---|---|
| STACKIT | 5.0 | |
| Hetzner Cloud | 4.0 | |
| AWS European Sovereign Cloud | 3.0 | |
| IONOS Cloud | 3.0 | |
| T Cloud Public | 3.0 | |
| UpCloud | 3.0 | |
| Exoscale | 3.0 | |
| Delos Cloud | 3.0 | |
| Microsoft Sovereign Cloud | 3.0 | |
| SysEleven OpenStack Cloud | 3.0 | |
| Cloud Temple Trusted Cloud | 3.0 | SecNumCloud qualification requires a high security baseline. Secure by default implied by ANSSI requirements. Network firewall (Stormshield) available. |
| pluscloud open | 2.0 | |
| noris Sovereign Cloud | 2.0 | |
| Infomaniak Public Cloud | 2.0 | OpenStack security groups configurable. Default behaviour not documented as 'deny'. ISO 27001 security baseline. |
| OVHcloud Public Cloud (inkl. SecNumCloud) | 1.0 | |
| Oracle EU Sovereign Cloud | 1.0 | |
| Scaleway | 1.0 |